← All transcripts

2026 Cost of a Data Breach Report: AI Is Changing Cybersecurity Transcript, AI Summary & Key Points

IBM Technology · 7 days ago · Education · 17:31 · EN

📄 Transcript

Searchable transcript of 2026 Cost of a Data Breach Report: AI Is Changing Cybersecurity — IBM Technology (17:31). Search for a phrase, then click its timestamp to jump straight to that moment in the video.

Captions sourced from the original video on YouTube, published by IBM Technology. The video, its captions and all related intellectual property remain the property of their respective owners; AINotes claims no ownership. Provided for research, accessibility and search — see the Transcript Notice and Copyright Policy.

00:00 Powerful new AI frontier models are revolutionizing cybersecurity. Models like Anthropic Mythos and similar ones from other vendors are popping up everywhere and exposing security vulnerabilities that have been lying just under the surface for decades. Their ability to have identified these gaps with a velocity and volume never seen before is compressing attack timelines.

00:23 The cost of delay will soon be measured in minutes, not in months. Today, every hour a breach remains active costs organizations roughly $1,100. And that's gonna add up. That's just one of many findings in this year's Cost of a Data Breach report. IBM has contracted the Ponemon Institute once again to survey thousands of organizations who've suffered data losses in order to keep our finger on the pulse of these attacks.

00:53 And what we've learned, we share with you so that you can improve your defenses. Lessen the odds that you'll be the basis for next year's report. Let's take a look at the 2026 Cost of a Data Breach report and see what it taught us, where we need to improve, and what we can do about it. There are tons of security reports out there with all kinds of scary statistics.

01:16 So why should you believe this particular one? Well, the first thing to understand is this is independent. We contract with the Ponemon Institute, a separate organization, And they've been doing these reports for 21 years. So they kind of got this figured out. They've been this for long enough to know what works and what doesn't. Like for instance, if they find a data breach was really high value or extremely low, those extremes that are out there on the bell curve, we're just going to eliminate those from the report

01:45 because for instance one of these that might be really large would skew what would be the average. So we don't want to overstate what the results are. We want it to be realistic. So because we've got 21 years, that's a lot of longitudinal data across more than two decades, where if you were to see, is there a trend that's happening? Well, you can tell because you've got two decades worth of data.

02:12 And ultimately, IBM's not just out cherry picking certain responses to make a particular point. We're again, trying to get the most accurate reading of what these things would be. Now, who did they go talk to? If they just go out and talk to two or three people, that's not very meaningful. But this study, they went out and talked to about 600 organizations that were impacted by data breaches in the last year.

02:37 And in those organizations, they interviewed about 3,500 leaders from the security team, from the C-suite business leaders. All of these people had firsthand knowledge of the particular breach and what happened from it. And these were not skewed into one area. They were across 17 different industries and from 16 different countries. So the data breaches that we saw were from a wide sample and they represented a wide range in terms of magnitude.

03:10 All the way from one breach that was about 2,500 records all the way up to one that was on the order of 115,000 records. So that gives you an idea of why you should trust the results I'm about to tell you about. Okay, so what did we learn? Well, first the bad news, but hang on. I promise there's gonna be some good news as well. So just sit tight. So what we learned is some things never change, and yet some do.

03:40 But some of the things that didn't change, let's take a look at the causes of data breaches plotted across their cost. And across the frequency of these particular causes. So what we found in this year's report is that one of the things that didn't change, number one, in both cost and in frequency, phishing attacks. That's one we need to improve on.

04:06 And by the way, if you're scoring at home and you wanna know what the others that really mattered here, number two, in terms of cost, social engineering. And number two, in terms of frequency, this was supply chain issues. So we're gonna see, in fact, more of those as we start moving into using AI and models that come from all sorts of places that we haven't really verified all that well.

04:31 So those are the things, if you wanna know what will cut down on the cost of a data breach, we really need to start looking at some of these things. What was the response time? Well, our response time, it turns out, was if you think about response time, you can break this down into a couple of different dimensions. One is to consider the mean time to identify.

04:51 That's how long it takes once the bad guy has gotten into your system before you're aware of it. And that took on average 183 days. Yeah, that's a long time. And then how long did it take after that for us to actually contain and mop up? Well, that was 64 days. So if you look at this timeline, add these up, you're looking at 247 days. Okay, that's two-thirds of a year.

05:21 That is way too long for the bad guy to be in your business and making off with data. We have got to do better than this. It turns out that this total number actually increased by six days as compared to last year's averages. So, we had seen... a decline in the previous year, well, we just made up for it with this year's report. But the bottom line is, this number is in line with the 10-year average.

05:49 So as much as we try, as much we're improving in some areas, this is an area that I keep harping on every year when I do this report. I want to see this number go down, I think we all do. But this has been a big struggle for us as an industry, if we look at this. Another thing that really didn't change the impact of ransomware. It's still a big deal and it's still hurting us.

06:13 We're seeing that ransomware in fact got worse. It went from 34% up to 39% of data breaches resulting here. So we're moving in the wrong direction and attackers are shifting to higher impact pressure tactics where they start not just taking your data but they're really targeting and trying to get you to pay through extortion. They're targeting your brand reputation.

06:39 They're targetting your employee data, which they can then use for other situations like financial fraud and things of that sort. And they're targeting your intellectual property, your keys to the kingdom. That's what didn't change. So let's talk about what did change. Well, obviously this is the cost of a data breach report. So the question everyone wants to know, how much does a data breach cost?

07:03 Well, it turns out If you look at the worldwide number, it's now on the order of $5 million per incident. That's the average. So that means there were some that were a lot more and some that we're a lot less, but that's again taking out the really big numbers from really massive breaches. And we still ended up with this as an average score. And the other thing to think about this, well, that's up 12% from last year.

07:32 Inflation, maybe. Not enough to account for that, though. So this is a situation, and if you look at last year's report, we actually had a slight decrease. Well, again, we made up for it this year. So this not moving in our direction the way we'd like it to. And then if you looked at the US numbers, well, it was even worse. The US cost of a data breach average number, how about this, 11.5 million.

08:00 That's more than 2X what it was for the worldwide number. I don't know if the bits in the US are just more expensive or what, but there's a lot more consequences that go in some cases in some countries where reporting and things like that can affect these numbers. But these numbers are not really what we want to see. It means this is expensive. It means we need to do better in order to make sure we're not sinking ourselves.

08:27 And what was a big factor in a lot of these that we found from the report? This won't come as a surprise or it shouldn't, AI. So AI we found was causing a 56% increase in generated AI attacks. So AI is off now attacking people in addition to all the other things that, good things that it can do, it can also do that. We found that one in four organizations that were breached had some form of AI that was involved in the attack.

09:03 And we're seeing things like deepfakes getting used more. Deepfakes are AI generated impersonations, videos, pictures, and things like that. But a deepfake of your boss calling you and telling you to send money to another place or tell you what their password is or something like that, these are very convincing and we're starting to see a rise in those.

09:23 We're also seeing a rise in AI generated malware, because one thing we know is that AI can generate code and the code it can generate it can be good code or it can be bad code, does harm or does good. And AI-driven attacks, when they occurred, well, we found that they drove an additional $1 million in cost per breach if AI was involved in this situation.

09:48 So, other things that we looked at, well 92% of organizations, that's a large number, regardless of what I'm about to tell you next. 92% of these lacked proper access controls for their AI. These are the AI-related breaches. 92% lacked basic access controls. That's a failure. That's big failure and we should know better. In other words, it wasn't model failure, but it was things like APIs and apps and things like that, that ended up being attacked in these cases.

10:26 Plugins, those kinds of things were where the bad guys were able to get in. One of our classics remains misconfigurations of cloud environments. So if we don't get that stuff right, it makes these numbers continue to rise. Okay, Mr. Sunshine, where's all this good news that you promised? Well, I'm glad you asked. So one of the things that we saw was that there were some areas where there were significant savings from some organizations once they had a breach.

10:55 And one of things that they had in common was an extensive use of AI and automation. This makes a difference if you use that. In fact, we found that it was able to reduce the cost of a data breach on the order of $2 million. So that's a nice savings. Another area that saved was we reduced the breach time by roughly 65 days on average. So that means the bad guys are in there doing less damage and costing you less.

11:26 So nothing but good sides here. And deploying AI agents we found that there were about 50% of organizations that were doing this in their SOC for threat detection and response. So there's reason for optimism as we see organizations leveraging AI to do a better job. However, only 18% were really using these new foundation models in order to do vulnerability management.

11:56 Now it's relatively new here, so that may be the explanation. But clearly there's more work to be done if we're gonna get the maximum advantage and we wanna squeeze all of that out that we can. Listen, the attackers are gonna use AI to shorten the exploit windows. So that means we've got to respond in kind. We've got do essentially the same thing. Okay, so that was some good news that we could use AI and automation to improve the results of data breaches and minimize their risk.

12:27 What can we be doing going forward? Recommendations that come out of the report. For instance, one of the things is, we should be leveraging these frontier AI models. We can use them to discover vulnerabilities and shorten the time between discovery and exploitation. If we find the problem before the bad guys do, then we get a head start and we get to fix it before they get a chance to exploit it.

12:54 We've got to move from what has been human speed to machine speed. Because machines are doing a lot of these attacks. So doing things the way we've always done it is not gonna be fast enough. How do we do that? Well, should be pretty obvious. Use AI, use agents, use things like that in a controlled setting so that we can respond faster and keep up with the rate of the attacks coming in.

13:23 So we're gonna leverage these new models in order to find vulnerabilities and fix these gaps. Another area that's really important here is this area of non-human identities. So what are we talking about here? AI agents that I've just been talking about, those things need identities. They need to run under certain privilege levels. Not only just the ones we're using for security, but the ones that are being used throughout the business.

13:47 And what we're finding is that these sets of nonhuman identities, they're orders of magnitude more than what we are used to dealing with. Some people are estimating it's 50 to one, non-human identities to human identities. The agents have all these identities that people have far fewer. And we haven't historically been able to do identity management at the speed that is often required.

14:12 But these non-humans identities that are being used by agents, these things are gonna be ephemeral. They're gonna pop up and then they're gonna disappear. We need them and then we don't. We need this to be a frictionless environment. We need to be able to automate this whole process because if we don't do it, we're not gonna be able keep up. Other areas that we need to take a look at would be AI sovereignty.

14:37 This is a topic that's coming up in a lot of discussions these days. We've always had the need to do visibility and control in security environments. You know, I can't secure what I can see and if I can control it, then it's anybody's guess what will happen. AI is not different, and we're starting to realize that and starting to put some focus on it, that we need to know where my data is.

15:02 I need to how it's being used, and I need know who has access to all of this stuff. And then, finally, the other thing I'm gonna leave you with, it deals with cryptography. So, cryptography is an area where we found that there was a major failure. In fact, only 37% of organizations had their sensitive data encrypted when the data was breached. 37%, come on folks, that's not gonna get it done.

15:33 We know if the data is sensitive, it has to be encrypted. So that's something that we need to be able to block that exposure that we're seeing on a regular basis. And there's another exposure that's coming in the future. Even if you did a great job and you encrypted all of your sensitive data, quantum computers are coming. And those quantum computers one day will be strong enough to be able to break our existing cryptography.

15:59 And we call that Q day whenever that finally occurs. So we gotta be ready for that. The good news is we have new crypto algorithms, post-quantum crypto algorithms that we can re-encrypt all of our data with now and it will be secure, we believe, against the quantum threat. But that means you need to start now because if attackers are harvesting your data now, they'll be able to decrypt it later and you won't be able to do anything about their copy that they've already made.

16:26 So we need to build in this notion of crypto agility so that when we need to make changes we can make those changes more easily in the future going forward. I think it's safe to say that we have our work cut out for us. We can't just throw more people at the problem but what we can do is work smarter and that begins with learning from each other. Things like the 2026 IBM Cost of a Data Breach report.

16:51 And then leveraging AI and automation as force multipliers to improve defense. One last statistic for you. We found that 85% of organizations say that AI frontier models like Mythos are actually gonna drive increased security investment. That's a positive trend toward a more effective defense. Attackers are already using this technology to their advantage. We need to use it even better.

💡 Answer

AI is changing cybersecurity by accelerating attacks and increasing breach costs, while also enabling faster vulnerability discovery, automated response, and lower breach impact when deployed with proper controls.

🧠 AI Summary

The 2026 Cost of a Data Breach report finds that breaches now cost an average of $5 million worldwide and $11.5 million in the US. Phishing remains the leading cause by cost and frequency, ransomware rose from 34% to 39% of breaches, and the average breach lifecycle reached 247 days. AI is increasing attack speed and cost, with one in four breached organizations reporting AI involvement, but AI and automation can reduce breach costs by about $2 million and shorten breach time by roughly 65 days. Organizations need to adopt AI-driven vulnerability management, automate non-human identity management, improve AI visibility and access controls, encrypt sensitive data, and prepare for post-quantum cryptography.

🔑 Key Points

  • The average worldwide data breach costs about $5 million, up 12% from the previous year.
  • The average US data breach costs $11.5 million.
  • Phishing ranks first for both breach cost and frequency; social engineering ranks second by cost, and supply chain issues rank second by frequency.
  • Organizations took an average of 183 days to identify breaches and 64 additional days to contain them, totaling 247 days.
  • Ransomware accounted for 39% of breaches, up from 34%.
  • One in four breached organizations had some form of AI involved in the attack, and AI-driven attacks added $1 million per breach.
  • AI and automation reduced breach costs by about $2 million and shortened breach time by roughly 65 days.
  • Only 37% of organizations had sensitive data encrypted during a breach.

✅ Actionable items

  • Use frontier AI models to discover vulnerabilities before attackers find and exploit them.
  • Deploy AI agents and automation in controlled settings for faster threat detection and response.
  • Automate identity management for ephemeral non-human identities used by AI agents.
  • Establish visibility and control over where AI data is stored, how it is used, and who can access it.
  • Encrypt sensitive data and adopt post-quantum cryptographic algorithms.
  • Build crypto agility so encryption can be changed more easily as threats evolve.
  • Implement basic access controls for AI APIs, applications, plugins, and related systems.

🧰 Tools & AI usage

  • Anthropic Mythos — AI frontier model associated with discovering security vulnerabilities.00:05
  • AI agents — Support threat detection, response, and business operations under controlled privilege levels.11:09
  • Post-quantum crypto algorithms — Re-encrypt data to protect it against future quantum threats.16:08

AI is used for

  • Vulnerability discovery — Identify security gaps before attackers exploit them and shorten the time between discovery and exploitation.12:32
  • Threat detection and response — Accelerate security operations and reduce breach duration.11:09
  • Vulnerability management — Use foundation models to improve vulnerability management.11:49
  • Automated non-human identity management — Manage the large number of temporary identities used by AI agents.13:32

📊 Numbers mentioned

Costs

  • AI and automation reduced breach costs by about $2 million

Growth

  • Ransomware increased from 34% to 39% of breaches
  • The worldwide average breach cost increased 12% from the previous year
  • AI-generated attacks increased 56%

Pricing

  • $1,100 per hour for an active breach
  • $5 million average worldwide breach cost per incident
  • $11.5 million average US breach cost per incident
  • AI involvement adds $1 million per breach

⚖️ Advantages, risks & lessons

Advantages

  • AI and automation can reduce breach costs and shorten breach duration.
  • Frontier AI models can identify vulnerabilities at machine speed.
  • Post-quantum cryptography can protect data against future quantum threats.

Risks

  • AI is accelerating attack timelines and increasing the volume of discovered vulnerabilities.
  • Deepfakes can impersonate executives to request money or passwords.
  • AI-generated malware can be used for harmful purposes.
  • Insufficient AI access controls expose APIs, applications, plugins, and related systems.
  • Quantum computers may eventually break existing cryptography.
  • Attackers can harvest encrypted data now and decrypt it later.

Lessons

  • Organizations need to reduce breach identification and containment times.
  • Security defenses must move from human speed to machine speed.
  • AI adoption requires strong access controls, visibility, and identity management.
  • Sensitive data encryption remains an essential baseline defense.
  • Crypto agility should be built before post-quantum migration becomes urgent.

💬 Quotes

The cost of delay will soon be measured in minutes, not in months.

Captures the shift toward faster AI-enabled attack timelines.00:23

We need to move from what has been human speed to machine speed.

Summarizes the required change in cybersecurity response.12:54

👤 People & companies

Anthropic

Vendor associated with the Mythos AI frontier model.

00:05
IBM

Organization associated with the Cost of a Data Breach report.

00:42
Ponemon Institute

Independent organization contracted to survey organizations affected by data breaches.

00:22